IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: How To Check If The Service Account Has Correct Active Directory Permissions

App Control: How To Check If The Service Account Has Correct Active Directory Permissions

Environment

  • App Control Server: All Supported Versions
  • Microsoft Windows: All Supported Versions

Objective

To verify if the App Control service account has the correct permissions needed to query all Active Directory domains and subdomain in the forest where AD users reside

Resolution

  1. Login to the server system hosting the App Control app with the AD service account used by App Control services
    • To find it > Open Services.msc > CB App Control Server > Log On As
  2. Download and run Microsoft AD Explorer
  3. Within AD Explorer enter:
    • Connect to: <Domain Name>
    • User: <Service Account>
  4. To confirm permissions:
    • If the connection and browsing the OUs where the AD users reside succeeds then the permissions are correct
    • If the connection fails, then this means that permissions are not correct and need to be addressed by an Active Directory admin

Related Content


 

Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-11-2018
Views:
3853
Contributors